Privacy policy
What we hold, why we hold it, and what we cannot see.
Written to be checked rather than admired. If any line here disagrees with how a product actually behaves, the product is wrong and we want to hear about it.
Last updated 1 August 2026
Who we are
MZEUS LABS LLP(“MzeusLabs”, “we”) is a limited liability partnership incorporated in India, LLPIN ACV-7859, registered in Pune, Maharashtra, India. We are the data fiduciary for personal data described in this policy.
This policy covers ShareLync, Mann and this website. Each product also has its own in-app privacy notice; where a product notice is more specific, it governs that product.
The short version
Your writing is encrypted on your device before it is stored, and our servers hold ciphertext. We do not describe our products as end-to-end encrypted, because we hold ourselves to what that term means: requesting an AI reflection sends that entry for processing, and it is not retained afterwards.
How that protection is built is described on the security & privacy page.
What we collect
Account information
- Email address, name and, where you provide it, a phone number
- Authentication identifiers issued by Firebase Authentication
- Language, notification preferences and timezone
- Subscription status, where you buy a paid plan
ShareLync
- The biodata you create, stored encrypted. The key is derived from the share link and is never stored on our servers
- Who you have shared with, so that you can revoke access later
- View counts and basic engagement on a profile you own
Mann
- Journal entry bodies and mood notes, encrypted on your device
- Entry metadata such as mood score, tags, word counts and timestamps, which the app needs in order to list and sort your entries
- Onboarding answers, which may include gender and pronouns, your reasons for journalling, and living situation. We name these rather than folding them into “account information”
- Chat messages and their timestamps
This website
If you send us a message or join a waitlist, we store what you typed and your email address so we can reply. We do not run advertising trackers or third-party analytics profiling on this site.
Why we hold it
- To run the service you asked for: creating and sharing a biodata, saving and reflecting on an entry, signing you in
- To keep it working and safe: diagnosing faults, preventing abuse, enforcing rate limits and detecting anomalies
- To meet legal obligations: tax, accounting and lawful requests
- To improve the products: using aggregate usage patterns, not the content of your entries
We do not sell personal data, and we do not use the content of your journal entries or biodata to train models.
Who processes it with us
We use a small number of processors, each bound to handle data only on our instructions:
- Google Firebase and Google Cloud: authentication, database, file storage, hosting and push notifications. Our primary database region is asia-south1 (Mumbai)
- Google Gemini: generates a reflection when you ask for one. Entry text is sent for that request and is not retained
- Razorpay: payments, where you buy a paid plan. We do not see or store your card details
- Email delivery: to send you transactional email you have asked for
Some processors operate outside India. Where data is transferred, we rely on the processor’s contractual commitments and the transfer conditions permitted under applicable law.
How long we keep it
- While your account is open: your content stays until you delete it or close your account
- On deletion: we delete your content and account data from live systems, and it ages out of backups within 30 days
- Records we must keep: invoices and tax records are retained for the period Indian law requires
- Consent records: where somebody consented to a biodata being shared, we keep a record of the consent itself, so the audit trail survives even after access is withdrawn
Your rights
Under the Digital Personal Data Protection Act, 2023 and comparable laws, you can ask us to:
- Give you a copy of the personal data we hold about you
- Correct anything inaccurate or incomplete
- Delete your data and close your account
- Withdraw a consent you previously gave
- Nominate someone to exercise these rights if you cannot
Both apps let you delete everything from inside the app. If you would rather we did it, write to alefiya@mzeuslabs.com and we will act within 30 days.
Because Mann encrypts entry bodies with a key we do not hold, we are unable to recover entries on your behalf if you lose access to your account. This is a consequence of the encryption design.
Children
Neither product is intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, write to us and we will remove it.
Security
Entry bodies and biodata contents are encrypted before they leave your device. Access to production systems is limited to the people who need it. Our database access rules are enforced server-side rather than in the client. No system is perfect, and we will tell you plainly if something goes wrong that affects you.
To report a vulnerability, write to alefiya@mzeuslabs.com. We will confirm we have read it and tell you what we did.
Changes and contact
If we change what we store or send, we change this page in the same week, and we date it. Material changes are notified in the app.
For any privacy question or grievance, write to alefiya@mzeuslabs.com, addressed to the Grievance Officer, MZEUS LABS LLP, Pune, Maharashtra, India. If you are not satisfied with our response, you may complain to the Data Protection Board of India.